Re: dpkg MD5

Jeremy Stanley <[email protected]> Thu, 7 Nov 2024 23:37:41 +0000
Newsgroups gmane.linux.debian.devel.security
Message-ID <[email protected]>
On 2024-11-07 16:45:54 -0500 (-0500), David Campbell wrote:
[...]
> dpkg currently uses MD5 to verify packages, but MD5 is considered
> insecure, why not switch to SHA256 (and also update lintian)?
[...]

MD5 is considered insecure to collision attacks, but mounting one
would require that the creator of the original file intentionally
pick content that can hash to the same value as some malicious
content (and even that is nontrivial, but let's set that aside for
the moment).

https://en.wikipedia.org/wiki/Collision_attack

What you're probably worried about is preimage resistance of the
algorithm (and in particular, second preimage resistance, which is
what keeps some random attacker from creating a file which hashes to
the same value as a known good file).

https://en.wikipedia.org/wiki/Preimage_attack

MD5's preimage resistance is not in question presently, that I've
heard, and it would be pretty big news in the cryptography community
if it were.

> Please, include my email address in the CC if you respond to this
> message. I am not subscribed to the mailing list.
[...]

Sorry, GMail doesn't accept messages from my mailserver, and I'm not
going to bother jumping through hoops just to appease them. Anyone
who's interested in Debian security matters should subscribe to the
mailing list or read its archives in a Web browser at the very
least.
-- 
Jeremy Stanley
signature.asc (application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE-----

iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAmctTz5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3
QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ
WCnc2A/6Ajqldxzx+5zv+5bIkdWIFJ8WtcUGgaAWwnNnm5BTdIAMJIK3/Qvrr/zD
PcZcTPmiVhQS9TN2FZdveZON2XBY9smAfua6qbJJWCYK7wu/2FNpqRlTiPZHXk7Z
+hMkQ54zgtSv45ZtzjsVSFCCXBsProaHEQCJewigFrwcJNfEcVtiOdH2FPStBvfT
QFNs4A+iJdbIGxI4wNKzzdmSb1EzHVKkwEUlW24gAfNV+glUI0ml1XWnP15cdhc4
eYoZhyFib4LzTb+vip0BCq9tq/qaeItPP2BB9NEnF40woG9IHxGG3Uuywk8V0DPW
NHQEUb794xadxpTqhRwqzarCg82op7A6Qyz2GS764luIx1dlxc6upRtGjM4iUHMb
FsibHTcPHXyLkwWp0AuS9NnWUtLP8ZDN3kOIElr3a87B1WH5Q5IynmhauwifH0aD
w6a7xdovI1lKEYnE1Y9o8ajDTRepD0YShEI66UG3kBHl2YxtvzzLi3vV4rGl95q3
HXuJFFN4Bvp9UeT3azxZQKBQLBJhoMRsw/zja7pS5NmBpWMiqlpJuKmDQzhQ5++s
coUk/DA7CJinIVohA7AZV7wtplXOnlL8bnOA0pcc8g/gjpL7W9sadwPaMaomUFhO
zP6y0Fl2f6Ey3J1qgkXWBEK+DUXNSLCNQZGexncu1hY05grvsT8=
=91Dl
-----END PGP SIGNATURE-----